* Florian Weimer wrote: > * Lutz Donnerhacke: >> Currently the attack looks like exploiting insufficient highest bit >> handling of the internal state variables. This is a matter if the >> protocol applies a random(!) padding directly before hashing. > > Source? Personal impression. > (The impact on V3 keys could be interesting, though.) Of course.